CVE-2014-3182: Buffer Overflow
Array index error in the logidjrawevent function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORTTYPENOTIFDEVICEUNPAIRED value.
Other sources
Linux kernel built with the Human Interface Device(HID) Bus support(CONFIGHID) along with a Logitech Unifying receivers full support(CONFIGHIDLOGITECHDJ) driver, is vulnerable to an OOB read flaw. It could occur if a device offers a malicious HID report with arbitrary deviceindex.
A local user with physical access to the system could use this flaw to crash the system resulting in DoS.
Upstream fix: ------------- -> https://git.kernel.org/linus/ad3e14d7c5268c2e24477c6ef54bbdf88add5d36
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3182?
CVE-2014-3182 is considered a high severity vulnerability due to its potential for executing arbitrary code or causing a denial of service.
How do I fix CVE-2014-3182?
To fix CVE-2014-3182, update the Linux kernel to version 3.16.2 or later.
Which versions of the Linux kernel are affected by CVE-2014-3182?
CVE-2014-3182 affects all Linux kernel versions before 3.16.2, including those from 3.2.0 to 3.16.1.
What type of attack does CVE-2014-3182 allow?
CVE-2014-3182 allows physically proximate attackers to potentially execute arbitrary code or cause system crashes.
Is there a patch available for CVE-2014-3182?
Yes, patches for CVE-2014-3182 are included in kernel versions 3.16.2 and later.